PT-2026-78894 · WordPress · Kirki

CVE-2026-74992

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kirki versions prior to 6.2.3
Description Users with the Editor role can upload arbitrary files to a web accessible directory because the plugin fails to properly validate files within uploaded archives and does not remove unwanted files after extraction. This flaw can lead to Stored XSS (Cross-Site Scripting, where malicious scripts are permanently stored on the server) and RCE (Remote Code Execution, allowing an attacker to execute arbitrary commands) on certain server configurations.
Recommendations Update Kirki to version 6.2.3 or later.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74992

Affected Products

Kirki